Live data from Hacker News

Petition UK government to not ban encryption

petition.parliament.uk

61–70 of 113 posts

Re: Petition UK government to not ban encryption

#61
post #27
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

The problem with your interpretation is that bank communications are still a means of communication. So the vagueness of the law allows politicians to extend their requirements to any product they wish without exception. This isn't something I believe to be accidental either as terrorism laws are often written to be vague with the intent of common sense regulation - which often gets bypassed when a jobsworth believes…

"means of communication" is not in the text of a law. It was a quote from David Cameron. As yet, there is no law.

I think it's reasonable to assume that the terms would be more explicitly defined in an actual law.

Re: Petition UK government to not ban encryption

#62
post #16

Urgh. This should be better phrased. From the BoingBoing article: David Cameron says there should be no "means of communication" which "we cannot read" It's very specific to communication, and reading between the lines, messaging, as opposed to something like HTTP communication between a bank and a customer. Don't get me wrong, it's still incredibly stupid, but the government will be able to reply to this petition wi…

Reading "between the lines" is not a valid way to interpret laws. What is written is what is valid, not what you think it should mean. As yourself used the term, how is "communication between a bank and a customer" not a form of "communication"?

"means of communication" is a quote from David Cameron, and is not the actual valid text of a law. It's hardly uncommon for a politician to sum up the intent of a law while not using the precise language used inside it.

In any case, there is no law yet, so no language to examine.

Re: Petition UK government to not ban encryption

#63
post #58
post #34

Earlier quoted context omitted.

I expect that a government may be very interested in the content of communications between a bank and a customer

Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway. Webmails, social medias or dating services are of a much greater interest to a nosy government.

I can't see how, without any context, you can say that "Webmails, social medias or dating services are of a much greater interest to a nosy government". As to regulations, if it is the law that backdoors are mandatory, then banks have no say in this.

Re: Petition UK government to not ban encryption

#65
post #30

Earlier quoted context omitted.

How can you have a situation where the HTTPS used to secure communication between two peers is different than the HTTPS used between a bank and one of it's clients ? This just shows serious misinformation on your part.

Presumably the government asks the bank what you're up to, and the bank tells them. Which is exactly what already happens today. Do you think the reason you use HTTPS to talk to your bank is to prevent the government from seeing your account balance?

It's certainly not the only reason but sure it's one of them. Proof of that is Google forcing TLS encryption of all it's traffic after the NSA scandal.

Re: Petition UK government to not ban encryption

#66
post #55
post #43

Earlier quoted context omitted.

I don't think that you understand that the TLS technology used for online banking (which would still be legal) is the very same technology that lets you create a secure communication channel with other users.

I don't know why you think that. Perhaps I was unclear. The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I b…

TLS is currently simply a matter of point and click on a graphical interface.

For hosting provider setup, to domain name registration and TSL certificate generation there are thousands of online tutorials.

You don't need to be an expert or a developer to know how to setup TLS on a Wordpress blog.

Re: Petition UK government to not ban encryption

#67
post #58

Earlier quoted context omitted.

Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway. Webmails, social medias or dating services are of a much greater interest to a nosy government.

Oh, I believe you are mistaken. Governments are quite interested in your financial dealings, even with banks. The more they know, the less you can do without their direct knowledge.

I am not saying they are not interested. I am saying that they just need to ask the banks who will hand over everything no question asked. GCHQ does not need to intercept your connection to get your bank statement.

Re: Petition UK government to not ban encryption

#69
post #63
post #58

Earlier quoted context omitted.

Banks are so closely regulated that they are not really (in fact not at all) off limit for the government. Unless we are talking about a foreign website of a foreign bank, which would not be required to comply anyway. Webmails, social medias or dating services are of a much greater interest to a nosy government.

I can't see how, without any context, you can say that "Webmails, social medias or dating services are of a much greater interest to a nosy government". As to regulations, if it is the law that backdoors are mandatory, then banks have no say in this.

Because they are services hosted outside the UK and which are not heavily regulated. Banks not only provide everything the gvt asks but actually have a duty to act as a law enforcement agency, i.e. watching their customers on the gvt behalf. Facebook or Gmail aren't required to do that.

Re: Petition UK government to not ban encryption

#70
post #55
post #43

Earlier quoted context omitted.

I don't think that you understand that the TLS technology used for online banking (which would still be legal) is the very same technology that lets you create a secure communication channel with other users.

I don't know why you think that. Perhaps I was unclear. The average prospective terrorist / criminal etc isn't going to be able to set up TLS. If they encrypt their communications, the odds are it's going to be going via a third party. Next time you send an email, tell the recipient that from now on you're going to communicate directly by TLS, and they'll need to set up a server before you can talk to them again. I b…

Using PGP securely is as easy as downloading some software, typing in your message, and clicking a button. It's not something that requires any knowledge beyond basic computer usage. You aren't going to be able to stop people from sharing PGP software on the internet.

I think you're severely underestimating the intelligence of people in general. If we're talking about ISIS, all it takes is one moderately experienced computer user to show everyone else how to use PGP.

Post reply on HN